RBI master-direction RBI/DoR/2025-26/379 · 28 Nov 2025
Official title
Reserve Bank of India (Credit Information Companies – Managing Risks in Outsourcing) Directions, 2025
Summary
Check the official recordThe Reserve Bank of India (RBI) issues these Directions to govern the outsourcing of Information Technology (IT) services by Credit Information Companies (CICs). CICs must establish a Board-approved IT outsourcing policy that covers risk management, governance, and exit strategies. The Board and Senior Management retain ultimate responsibility for outsourced services. CICs must perform due diligence on service providers, maintain an inventory of outsourced services, and ensure robust business continuity and disaster recovery plans. Agreements must include specific clauses for data security, audit rights, and regulatory access. CICs must report cyber incidents to the RBI within six hours of detection by the service provider. Existing IT outsourcing agreements must comply with these requirements by April 10, 2026, or upon renewal, whichever is earlier.
What you must do
Key dates
Who is affected
Exceptions
RBI/DoR/2025-26/379 DoR.ORG.REC.No.298/21-04-158/2025-26 November 28, 2025
Reserve Bank of India (Credit Information Companies – Managing Risks in Outsourcing) Directions, 2025
In exercise of the powers conferred by Section 11 of the Credit Information Companies (Regulation) Act, 2005, and all other provisions / laws enabling the Reserve Bank of India (‘RBI’) in this regard, RBI being satisfied that it is necessary and expedient in the public interest so to do, hereby, issues the Directions hereinafter specified.
These Directions shall be called the Reserve Bank of India (Credit Information Companies - Managing Risks in Outsourcing) Directions, 2025.
These Directions shall come into force with immediate effect.
Provided that a Credit Information Company’s existing Information Technology (IT) outsourcing agreements regardless of whether they are due for renewal on or after the effective date of these Directions shall comply with the provisions of these Directions either at the time of renewal or by April 10, 2026, whichever is earlier. However, the Credit Information Company’s new IT outsourcing agreements that come into force on or after the effective date of these Directions, shall comply with the provisions of these Directions from the date of agreement itself.
Provided further that nothing in the preceding proviso shall be construed as permitting non-compliance with any other extant regulatory instructions or statutory requirements applicable to such arrangements.
These Directions shall be applicable to Credit Information Companies as defined under clause (e) of Section 2 of the Credit Information Companies (Regulation) Act, 2005, hereinafter collectively referred to as ‘CICs’ and individually as a ‘CIC’.
These Directions shall apply to a CIC’s material outsourcing of IT services, as defined in paragraph 6(3) of these Directions. In this context, ‘Outsourcing of IT Services’ shall include outsourcing of the following services:
(i) IT infrastructure management, maintenance and support (hardware, software or firmware);
(ii) network and security solutions, and maintenance (hardware, software or firmware);
(iii) application development, maintenance and testing by Application Service Providers (ASPs) including ATM Switch ASPs;
(iv) services and operations related to data centres;
(v) cloud computing services;
(vi) managed security services; and
(vii) management of IT infrastructure and technology services associated with payment system ecosystem.
(i) corporate internet banking services obtained by a CIC as a corporate customer or sub-member of another Regulated Entity (RE);
Provided that for the purpose of these Directions, the following indicative (but not exhaustive) list of entities shall be considered as REs - Commercial Banks; Local Area Banks; Small Finance Banks; Payments Banks; Regional Rural Banks; Non-Banking Financial Companies in Base Layer (NBFC - BL), Middle Layer (NBFC - ML), and Upper Layer (NBFC – UL); All India Financial Institutions; other CICs; Urban Co-operative Banks; Rural Co-operative Banks; and Payment System Operators.
For the purpose of these Directions, ‘Commercial Banks’ means banking companies (other than Small Finance Banks, Local Area Banks, Payments Banks and Regional Rural Banks), corresponding new banks, and State Bank of India, as defined respectively under clauses (c), (da), and (nc) of section 5 of the Banking Regulation Act, 1949.
(ii) external audit services such as Vulnerability Assessment (VA) / Penetration Testing (PT), Information Systems Audit, and security review;
(iii) SMS gateways (including bulk SMS service providers);
(iv) procurement of IT hardware or appliances;
(v) acquisition of IT software, product or application (e.g., Core Banking Solution (CBS), database, and security solutions) on a licence or subscription basis, and any enhancements made to such licensed third-party applications by the vendor (as upgrades) or on specific change request made by a CIC;
(vi) any maintenance service (including security patches, bug fixes) for IT infrastructure or licensed products, provided by the Original Equipment Manufacturer (OEM) themselves, in order to ensure continued usage of the same by the CIC;
(vii) applications provided by financial sector regulators or institutions such as Clearing Corporation of India Limited (CCIL), National Stock Exchange (NSE), Bombay Stock Exchange (BSE);
(viii) platforms provided by entities such as Reuters, Bloomberg, and Society for Worldwide Interbank Financial Telecommunication (SWIFT).;
(ix) any other off-the-shelf products (e.g., anti-virus software, and email solutions) subscribed to by a CIC, wherein only a license is procured with no or minimal customisation;
(x) services obtained by a CIC as a sub-member of a Centralised Payment System (CPS) from another RE;
(xi) Business Correspondent (BC) services, payroll processing, and statement printing.
(1) ‘Group’ shall be as defined in the Reserve Bank of India (Commercial Banks - Concentration Risk Management) Directions, 2025, as amended from time to time, for the purpose of intragroup transactions and exposures.
(2) ‘IT services’ means IT services / IT enabled services / IT activities.
(3) ‘Material Outsourcing of IT Services’ are those which:
(i) if disrupted or compromised shall have the potential to significantly impact the CIC’s business operations; or
(ii) may have material impact on the CIC’s customers in the event of any unauthorised access, loss or theft of customer information;
(4) ‘Outsourcing’ means use of a third-party (either an affiliated entity within a corporate group or an entity that is external to the corporate group) by a CIC to perform services on a continuing basis that would normally be undertaken by the CIC itself, now or in the future. 'Continuing basis' shall include agreements for a limited period.
(5) ‘Service Provider’ means provider of IT services including entities related to the CIC or those which belong to the same group or conglomerate to which the CIC belongs.
Provided that for the purpose of these Directions, the following indicative (but not exhaustive) list of vendors and entities shall not be considered as ‘Service Providers’ defined above:
(i) vendors providing business services using IT, (e.g., Business Correspondents (BCs);
(ii) Payment System Operators (PSOs) authorised by RBI under the Payment and Settlement Systems Act, 2007 for setting up and operating Payment Systems in India;
(iii) partnership based FinTech firms such as those providing co-branded applications, products, and services;
(iv) FinTech firms providing services for data retrieval, data validation and verification such as bank statement analysis, GST returns analysis, fetching of vehicle information, digital document execution, data entry and call centre services;